EvidenceSheet

A.5.20 Addressing information security within supplier agreements

Establish and agree the relevant security requirements in each supplier contract.

20
artefacts
2
held by a system
5
at each review
hard
to go live
Vendor register / contract repository
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Communication log with supplier on incidents · SIEM / log platform
  • Service level agreement security metrics report · SIEM / log platform

periodic reviewEvidence produced at each review

  • Signed supplier contract with security annex · Vendor register / contract repository
  • Risk assessment report for supplier · Vendor register / contract repository
  • Record of security incident notifications from supplier · Vendor register / contract repository
  • Monthly compliance dashboard · SIEM / log platform
  • Record of data sanitization verification after termination · HR system / LMS

governing documentDocuments that govern the control

  • Security requirements addendum · Vendor register / contract repository
  • Confidentiality and data protection clause · Vendor register / contract repository
  • Access control obligations schedule · Policy repository / GRC workspace
  • Supplier due diligence questionnaire · Vendor register / contract repository
  • Risk rating matrix · Vendor register / contract repository
  • Approval memo from risk owner · Vendor register / contract repository
  • Incident response clause in contract · Vendor register / contract repository
  • Incident handling workflow document · Document repository
  • Audit findings report on supplier · Policy repository / GRC workspace
  • Penalty notice for security breach · Policy repository / GRC workspace
  • Termination clause with data return and destruction requirements · HR system / LMS
  • Exit checklist for supplier · HR system / LMS
  • Certificate of data destruction · HR system / LMS

First move

Mostly documents and reviews. Pull the 2 system-held artefacts from your SIEM / log platform on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

A.5.19 Information security in supplier relationships · A.5.21 Managing information security in the ICT supply chain